CVE-2020-24356

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-24356
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-24356.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-24356
Aliases
Related
Published
2020-10-02T15:15:12Z
Modified
2025-07-01T11:22:18.475274Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

cloudflared versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, cloudflared searches for configuration files which could be abused by a malicious entity to execute commands as a privileged user. Version 2020.8.1 fixes this issue.

References

Affected packages

Git / github.com/cloudflare/cloudflared

Affected ranges

Type
GIT
Repo
https://github.com/cloudflare/cloudflared
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2018.*

2018.10.0
2018.10.1
2018.10.2
2018.10.3
2018.10.5
2018.11.0
2018.12.0
2018.12.1
2018.8.0

2019.*

2019.1.0
2019.10.0
2019.10.1
2019.10.2
2019.10.3
2019.10.4
2019.11.0
2019.11.2
2019.11.3
2019.12.0
2019.2.0
2019.2.1
2019.3.0
2019.3.1
2019.3.2
2019.4.0
2019.4.1
2019.5.0
2019.6.0
2019.7.0
2019.8.0
2019.8.1
2019.8.3
2019.8.4
2019.9.0
2019.9.1
2019.9.2

2020.*

2020.2.0
2020.2.1
2020.3.0
2020.3.1
2020.3.2
2020.4.0
2020.5.0
2020.5.1
2020.6.0
2020.6.1
2020.6.2
2020.6.3
2020.6.4
2020.6.5
2020.6.6
2020.7.0
2020.7.1
2020.7.2
2020.7.3
2020.7.4
2020.8.0